Impact
The vulnerability allows an unauthenticated attacker to reflect unsanitized user input into an HTML response. By luring a victim to a crafted URL, an attacker can execute arbitrary JavaScript within the victim’s browser session. This reflected XSS can be leveraged to steal session cookies, deface pages, or redirect users to malicious sites.
Affected Systems
Vendor: SCADA-LTS, Product: ScadaLTS, Affected Version: 2.7.8.1.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate to high severity. The EPSS score is not available, so the exact likelihood is unknown, but the vulnerability is listed as not in the CISA KEV catalog. Exploitation requires only a victim’s interaction with a crafted link and does not need authentication. The attack vector is therefore likely to be phishing or social engineering to entice a user to follow the malicious URL.
OpenCVE Enrichment